<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rex expression built with field extractor not working? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712384#M240330</link>
    <description>&lt;P&gt;I have a reliable base query to find events containing the information I want.&lt;/P&gt;&lt;P&gt;I built a rex using the field extractor, but applying the rex expression in a search does not yield any results, &lt;EM&gt;the values(gts_percent) column is always blank&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sample query:&lt;/P&gt;&lt;PRE&gt;index="june_analytics_logs_prod" $serial$ log_level=info message=*hardware_controller*|&lt;BR /&gt;rex field=message "(?=[^G]*(?:GTS weight:|G.*GTS weight:))^(?:[^\.\n]*\.){7}\d+\w+,\s+\w+:\s+(?P&amp;lt;gts_percent&amp;gt;\d+)"|&lt;BR /&gt;convert rmunit(gts_percent)|&lt;BR /&gt;chart values(gts_percent) by _time&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample raw_ result :&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bootcount&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:8&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;device_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;environment&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;prod_walker&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;event_source&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;appliance&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;event_type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;GENERIC&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;local_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2025-02-20T00:47:48.124-06:00&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;city&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;country&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;latitude&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:XXX&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;longitude&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:XXX&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;state&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;"},&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;log_level&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;info&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;martini::hardware_controller:&lt;/SPAN&gt; &lt;SPAN class=""&gt;GTS&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;17.05kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;tare&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;8.1kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;net&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;8.95kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;fill&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;6.8kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;percent:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;STRONG&gt;100%&lt;/STRONG&gt;\u0000&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;model_number&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;sequence&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:403659&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;serial&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;software_version&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2.3.0.276&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ticks&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1740034068&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp_ms&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1740034068124}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract the bold value in the raw, Where is my rex messing up?&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2025 18:13:05 GMT</pubDate>
    <dc:creator>nkavouris</dc:creator>
    <dc:date>2025-02-24T18:13:05Z</dc:date>
    <item>
      <title>Rex expression built with field extractor not working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712384#M240330</link>
      <description>&lt;P&gt;I have a reliable base query to find events containing the information I want.&lt;/P&gt;&lt;P&gt;I built a rex using the field extractor, but applying the rex expression in a search does not yield any results, &lt;EM&gt;the values(gts_percent) column is always blank&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sample query:&lt;/P&gt;&lt;PRE&gt;index="june_analytics_logs_prod" $serial$ log_level=info message=*hardware_controller*|&lt;BR /&gt;rex field=message "(?=[^G]*(?:GTS weight:|G.*GTS weight:))^(?:[^\.\n]*\.){7}\d+\w+,\s+\w+:\s+(?P&amp;lt;gts_percent&amp;gt;\d+)"|&lt;BR /&gt;convert rmunit(gts_percent)|&lt;BR /&gt;chart values(gts_percent) by _time&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample raw_ result :&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;bootcount&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:8&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;device_id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;environment&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;prod_walker&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;event_source&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;appliance&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;event_type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;GENERIC&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;local_time&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2025-02-20T00:47:48.124-06:00&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;location&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;city&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;country&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;latitude&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:XXX&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;longitude&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:XXX&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;state&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;"},&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;log_level&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;info&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;martini::hardware_controller:&lt;/SPAN&gt; &lt;SPAN class=""&gt;GTS&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;17.05kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;tare&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;8.1kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;net&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;8.95kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;fill&lt;/SPAN&gt; &lt;SPAN class=""&gt;weight:&lt;/SPAN&gt; &lt;SPAN class=""&gt;6.8kg&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;percent:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;STRONG&gt;100%&lt;/STRONG&gt;\u0000&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;BR /&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;model_number&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;sequence&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:403659&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;serial&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;XXX&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;software_version&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;2.3.0.276&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class=""&gt;ticks&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:0&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1740034068&lt;/SPAN&gt;&lt;SPAN&gt;,"&lt;/SPAN&gt;&lt;SPAN class=""&gt;timestamp_ms&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:1740034068124}&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract the bold value in the raw, Where is my rex messing up?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 18:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712384#M240330</guid>
      <dc:creator>nkavouris</dc:creator>
      <dc:date>2025-02-24T18:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rex expression built with field extractor not working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712389#M240331</link>
      <description>&lt;P&gt;The field extractor and &lt;FONT face="courier new,courier"&gt;erex&lt;/FONT&gt; commands tend to create overly complicated expressions.&amp;nbsp; This one should work.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=message "percent: (?&amp;lt;gts_percent&amp;gt;\d+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 18:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712389#M240331</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-02-24T18:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Rex expression built with field extractor not working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712394#M240332</link>
      <description>&lt;P&gt;this worked like a charm!&amp;nbsp;&lt;BR /&gt;thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 19:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rex-expression-built-with-field-extractor-not-working/m-p/712394#M240332</guid>
      <dc:creator>nkavouris</dc:creator>
      <dc:date>2025-02-24T19:30:18Z</dc:date>
    </item>
  </channel>
</rss>

